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FIG. 2 (a) 
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Network worm warning from 192. 168. 10. 254 
Date 2002/12/25 
Time: 11:30:45 

Target Node: 192. 168. 10. 15 
FQDN Name: Infector. infect, com 
NetBIOS name: Infector 
Username: Virus 

Detected request: /default. Ida? NNNNNNNNNNNNNNNNNNNNN 

NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN 
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%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090 

%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a 
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FIG. 2 (b) 



Network worm warning from 192. 168. 10. 254 

Date 2002/12/25 

Time: 11:30:45 

Target Node: 192. 168. 10. 15 

FQDN Name: Infector. infect, com 

NetBIOS name: Infector 

Username: Virus 

Detected path: C:¥!¥Windows ¥notepad.exe 
Current status: Attacking 

Arp information 
<Arp result> 
Ping information 
<Ping result> 
NBTSTAT information 
< NBTSTAT result> 
Netstat information 
<Netstat information> 
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